CVE-2019-6848
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/10/2019
Last modified:
19/04/2021
Description
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 CPU (BMEx58*) and Modicon M580 communication module (BMENOC0311, BMENOC0321) (see notification for version info), which could cause a Denial of Service attack on the PLC when sending specific data on the REST API of the controller/communication module.
Impact
Base Score 3.x
8.60
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:schneider-electric:modicon_m580_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:schneider-electric:modicon_m580:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:schneider-electric:modicon_bmenoc_0311_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:schneider-electric:modicon_bmenoc_0311:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:schneider-electric:modicon_bmenoc_0321_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:schneider-electric:modicon_bmenoc_0321:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page